Splunk Search

NULLの場合に他のフィールドの値を代入したい

1014502
New Member

お世話になります。

以下のようなデータがあります。
issue.id,Key
1111 2222
null 3333

issue.idがNUllの場合Keyの値をissue.idに代入したいのですが、どのようにすればよろしいでしょうか。

0 Karma
1 Solution

HiroshiSatoh
Champion

これで良いと思います。

(your search)
| eval issue.id=if(isnull('issue.id'),Key,'issue.id')

View solution in original post

0 Karma

HiroshiSatoh
Champion

これで良いと思います。

(your search)
| eval issue.id=if(isnull('issue.id'),Key,'issue.id')
0 Karma

1014502
New Member

ありがとうございます。無事に解決しました

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...